Quantum proof encryption, built to resist future quantum computer attacks, is the focus of a pilot anchored on the new NIST FIPS 204 post quantum digital signature standard, with banks and regulators at the table.
A Singapore-led consortium is using a test network to write, in public, the open-source reference architecture for how the financial sector migrates to post-quantum cryptography. If the plan holds, the deliverable is a shared playbook rather than another vendor product.
The Responsible Fintech Institute (RFI), a Singapore-based industry body, and Safeheron, a digital-asset security vendor, announced the cross-jurisdiction pilot on 24 August 2026. The work is anchored on ML-DSA-65, the digital-signature standard finalized as NIST FIPS 204, and runs on top of Safeheron's existing multi-party computation (MPC) wallet stack, a setup that splits signing keys across multiple parties so no single institution ever holds a complete key.
The pilot's narrow technical job is to test wallet generation and on-chain transfers using the FIPS 204 signature scheme on NEAR's quantum-resistant test network, not on any production chain. Its broader structural job is to produce a reference implementation that participating banks and regulators can review in the open, with the intent, both organizations said, to release the resulting code as a shared compliance and security reference.
"We're building a shared reference, not a product," RFI chairman Chia Hock Lai said in the announcement. Cross-jurisdiction, regulator-attended PQC pilots have mostly been paper exercises or vendor showcases, and the institute's pitch is that banks, custodians, and supervisors should be looking at the same code by the end of the exercise.
The test environment inherits Safeheron's production architecture: a multi-party-computation and trusted-execution-environment wallet layer with multi-chain coverage (Bitcoin, Ethereum, and other EVM-compatible networks) and APIs in TypeScript, Java, Python, and Go. The PQC layer is being added on top of that substrate rather than rebuilt from scratch, which both organizations frame as a deliberate decision to keep the migration path realistic for institutions that already run MPC custody.
Corroborating coverage from GeneOnline describes the same pilot with similar technical detail, though it does not name additional participants either. Specific participating banks and regulators are not enumerated in the primary announcement; they are referenced collectively as "selected financial institutions and regulatory stakeholders across multiple jurisdictions." That is a meaningful gap: a "cross-jurisdiction regulator" pilot whose regulators cannot be named is a different article than one where, for example, the Monetary Authority of Singapore and the Hong Kong Monetary Authority are publicly in the room.
The regulatory backdrop is concrete enough to make the framing plausible even before the participant list firms up. Earlier this year, MAS and the Association of Banks in Singapore established the ACT taskforce on AI-driven cyber and technology resilience, which sits inside the same supervisory conversation the pilot is now aiming to shape. Hong Kong, for its part, published a Fintech Promotion Blueprint in February 2026 that includes a Quantum Preparedness Index for assessing migration progress at supervised institutions, a tool that, if it travels, gives the pilot a place to plug into.
"Future quantum computers will break today's cryptography, and the AI acceleration curve is shortening the window," Safeheron chief security and policy officer Jag Foo said in the announcement. The line is the vendor's framing rather than independent assessment, and the pilot's own technical scope, which is signature-scheme testing on a test network, does not adjudicate it. The pilot is narrower than the quote suggests, and more useful in a different way: it gives the industry a single, written-in-public reference for what a FIPS 204-backed, MPC-shielded, multi-bank, multi-regulator wallet flow actually looks like in code.
Two things to watch. First, the open-source release, which is currently a roadmap promise rather than a product. If the eventual code lands as a Safeheron-branded framework with permissive licensing but governance captured by the vendor, the "shared reference" claim collapses. Second, the participant list. A pilot that names a small group of regional banks and at least one named regulator is a different signal from a pilot that does not. Both questions should be answerable by the time RFI and Safeheron publish their first technical milestone.